<?php
session_start();
echo $_POST['code'], '<br />';
echo $_SESSION['code'];
if (strtoupper($_POST['code']) == strtoupper($_SESSION['code']))
{
    echo '<br />ok';
}
else
{
    echo '<br />no';
}
?>
<!doctype html>
<html>
<head>
    <meta charset="utf-8">
    <title>无标题文档</title>
</head>
<body>
<form action="form.php" method="post">
<p>username:<input type="text" name="username" /></p>
<p>pass:<input type="password" name="pass" /></p>
<!--为防止浏览器的缓存，其后的url是变化的-->
<p>input code:<input type="text" name="code" onkeyup="if(this.value != this.value.toUpperCase())this.value=this.value.toUpperCase()"><img src="code.php" onclick="this.src='./code.php?'+Math.random()"></p>
<p><input type="submit" name="sub" value="login"></p>
</form>
</body>
</html>

